Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - If Cybersecurity Breaches Are Inevitable What Should Organizations Do About It?
Articles

If Cybersecurity Breaches Are Inevitable What Should Organizations Do About It?

ISBuzz TeamBy ISBuzz TeamJanuary 17, 2019Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
latest retail data breaches
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

There’s an inconvenient truth in the business community. As many business decision-makers are only too aware, hardly a week seems to go by without a data breach of some form being reported to press, and this year alone has witnessed some major breaches which have affected thousands of people around the world.

Just take a look at the stats. In October last year, DNA testing firmMyHeritage suffered a breachaffecting 92 million people. Fast forward to March this year, and we learnt that the data of87 million Facebook usershad been shared. Then in June,Ticketmaster revealedthat the login information, payment data, addresses, names and phone numbers of almost 40,000 people had been breached. And this was followed at the beginning of September, when hackers got into the systems atBritish Airways,impacting 380,000 transactions.

When they do happen, breaches of all sizes have brutal consequences (even if they are smaller than the examples cited above). Take a look at the retail sector alone – recent studies have shown that 19% of consumers would completely stop spending money with a retailer if the business had been breached, and one-in-three (33%) agreed they’d at least stop shopping there for a while. Can you imagine what losing 19% of your customer base might do to the bottom line? It certainly wouldn’t be a pretty sight.

With new regulations such as the GDPR taking hold, fines are also a big fear factor for business leaders. According to reports, Facebook’s fine for its part in the Cambridge Analytica scandal could have been 1.4bn in the post-GDPR world – a harsh sum even for a global giant like Facebook to stump up. And for small businesses too, the prospect of paying up to 4% of their annual turnover as a fine isn’t a fun one.

Where’s the business case for a budget?

So, the consequences of a data breach – from fines to financial losses and frustrated or deserting customers – are damaging, unnerving, and can put the businesses involved in jeopardy.

Against this backdrop, you might think it’s easy for chief information security officers to justify the need for their budgets. However, recent research[i]from Kaspersky Lab has shown that CISOs are actually struggling to get the budgets they require to fight off the cybercriminals.

There are several reasons for this, including the fact that security is sometimes lumped into the wider IT budget, that budget is being prioritized for digital, cloud or other IT projects, and due to ignorance on the part of the board. However, the most common reason is that it’s hard for CISOs to get budget when they cannot guarantee that their organization will not suffer a breach.

From a business point of view this might make sense, right? After all, if you are a business leader and concentrating on the bottom line, why would you agree to sink budget into a fight that apparently cannot be won? Sensible business protocol dictates that you should only invest where a return is on the cards.

It may sound controversial – to the business leaders reading this, anyway – but, at Kaspersky Lab we think the question: “can you guarantee there won’t be breaches anymore?” isn’t really a question that businesses should be asking. Before we explain why, let’s ask ourselves once again — are breachesreallyinevitable?

What makes cybersecurity breaches unavoidable?

According to our survey results, almost nine-in-ten (86%) CISOs believe that breaches are inevitable. So, what’s behind this certainty?

Well, most enterprises are on a path towards digital transformation, with over half (52%) agreeing that this is the tech trend that will have the biggest impact on the IT security of their organization in the next five years. Digital transformation widens the surface of attack, giving cybercriminals more opportunities to find weaknesses, to creep into systems, and to leak or exploit data. Cloud adoption, the increasing mobility of workforces, and the rise in use of digital channels, are all contributing factors here, increasing the risks.

And this isn’t the only factor that CISOs are up against. What if a malicious insider – an employee perhaps – was to single handedly work against a company, or even combine their efforts with those of an external attacker? To help them through the backdoor, so to speak?

This sort of threat could be especially difficult to identify and prevent in advance. In fact, it’s one of the most feared types of threats among the CISO crowd, with 29% of CISOs agreeing this is the biggest IT security risk facing their organization (second only to concerns about financially motivated cybercrime gangs at 40%).

And while we’re on the topic of financial motivation by the way, if breaching an organization promises to bring substantial gains to the attackers, and those gains exceed the resources they need to organize the attack in the first place, then as far as the criminals are concerned, their efforts are easily justified. They will just keep finding new ways to make their money.

Asking the right questions will lead to the right decisions

There seem to be plenty of reasons – outlined above – why the question ‘can I prevent an attack?’ is not the right one for business leaders to be asking. So whatisthe right question to ask?

Well, if attacks are likely and increasing, the crux of the issue really lies in whether a business can detect an attack quickly enough, and respond comprehensively and quickly enough to minimize its impact.

In other words, it’s becoming increasingly clear that businesses can’t live in the prevention only paradigm anymore. That mindset is simply outdated and out of sync with how businesses today work. When it comes to targeted, highly elaborated attacks, detection and response should instead be the priority.

It’s time to educate business leaders that it’s worth investing in cybersecurity. This is not about guaranteeing the complete prevention of cyber incidents, it’s about raising the price of attack for attackers. It’s about making an attack unaffordable, and not worth their while.

And, more importantly, it’s about getting your perimeter and security team ready to immediately address any attempt to interfere with your organizations’ network. An average breach costs a large enterprise up to $1.23 million — but if you take the necessary measures, this price will drop to a minimum, or even to nothing at all. Now that sounds like a sensible business decision.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

May 13, 20254 Mins Read

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}